Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-3167

Опубликовано: 12 апр. 2016
Источник: ubuntu
Приоритет: untriaged
EPSS Низкий
CVSS2: 6.4
CVSS3: 7.4

Описание

Open redirect vulnerability in the drupal_goto function in Drupal 6.x before 6.38, when used with PHP before 5.4.7, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a double-encoded URL in the "destination" parameter.

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

DNE

precise

ignored

end of life
precise/esm

DNE

precise was needed
trusty

DNE

trusty/esm

DNE

upstream

released

6.38
vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

wily

DNE

Показывать по

РелизСтатусПримечание
devel

not-affected

esm-apps/xenial

not-affected

esm-infra-legacy/trusty

not-affected

precise

not-affected

precise/esm

DNE

precise was not-affected
trusty

not-affected

trusty/esm

not-affected

upstream

not-affected

vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

Показывать по

EPSS

Процентиль: 69%
0.00632
Низкий

6.4 Medium

CVSS2

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
nvd
около 9 лет назад

Open redirect vulnerability in the drupal_goto function in Drupal 6.x before 6.38, when used with PHP before 5.4.7, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a double-encoded URL in the "destination" parameter.

CVSS3: 7.4
debian
около 9 лет назад

Open redirect vulnerability in the drupal_goto function in Drupal 6.x ...

CVSS3: 7.4
github
около 3 лет назад

Drupal Open redirect vulnerability in the drupal_goto function

EPSS

Процентиль: 69%
0.00632
Низкий

6.4 Medium

CVSS2

7.4 High

CVSS3